CVE-2010-1639
published 2010-05-26CVE-2010-1639: The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related…
PriorityP415medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.89%
85.4th percentile
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
Affected
81 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| clamav | clamav | <= 0.96 | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
| clamav | clamav | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wpfp-x7v8-4gqm: The cli_pdf function in libclamav/pdf
ghsa_unreviewed·2022-05-17
CVE-2010-1639 [MEDIUM] GHSA-wpfp-x7v8-4gqm: The cli_pdf function in libclamav/pdf
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
OSV
CVE-2010-1639: The cli_pdf function in libclamav/pdf
osv·2010-05-26·CVSS 4.3
CVE-2010-1639 [MEDIUM] CVE-2010-1639: The cli_pdf function in libclamav/pdf
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
Ubuntu
ClamAV vulnerabilities
vendor_ubuntu·2010-05-27·CVSS 4.3
CVE-2010-1639 [MEDIUM] ClamAV vulnerabilities
Title: ClamAV vulnerabilities
Summary: An attacker could send crafted input to ClamAV and cause it to crash.
It was discovered that ClamAV did not properly reallocate memory when
processing certain PDF files. A remote attacker could send a specially
crafted PDF and crash ClamAV. (CVE-2010-1639)
An out of bounds memory access flaw was discovered in ClamAV. A remote
attacker could send a specially crafted Portable Executable (PE) file
and crash ClamAV. This issue only affected Ubuntu 10.04 LTS.
(CVE-2010-2077)
Instructions: In general, a standard system update will make all the necessary
changes. For Ubuntu 10.04 LTS, this update uses a new upstream release,
which includes additional bug fixes.
Debian
CVE-2010-1639: clamav - The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote at...
vendor_debian·2010·CVSS 4.3
CVE-2010-1639 [MEDIUM] CVE-2010-1639: clamav - The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote at...
The cli_pdf function in libclamav/pdf.c in ClamAV before 0.96.1 allows remote attackers to cause a denial of service (crash) via a malformed PDF file, related to an inconsistency in the calculated stream length and the real stream length.
Scope: local
bookworm: resolved (fixed in 0.96.1+dfsg-1)
bullseye: resolved (fixed in 0.96.1+dfsg-1)
forky: resolved (fixed in 0.96.1+dfsg-1)
sid: resolved (fixed in 0.96.1+dfsg-1)
trixie: resolved (fixed in 0.96.1+dfsg-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s) [epel-all]
bugzilla·2011-01-04·CVSS 4.3
CVE-2010-1639 [MEDIUM] CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s) [epel-all]
CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s) [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include the bug IDs of the
respective parent bugs filed against the "Security Response" product.
Please mention CVE ids in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/?type_=security&bugs=595318
Please note: th
Bugzilla
CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s)
bugzilla·2010-05-24·CVSS 4.3
CVE-2010-1639 [MEDIUM] CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s)
CVE-2010-1639 Clam AntiVirus: Heap-based overflow, when processing malicious PDF file(s)
BBabba found a heap-based overflow flaw, in the way Clam AntiVirus's
command line anti-virus scanner performed scanning of Portable Document
Format (PDF) files. If a local user was tricked into scanning a
specially-crafted PDF file, it could lead to clamscan executable
crash, or, potentially, arbitrary code execution with the privileges
of the user running the clamscan tool.
Upstream bug report:
[1] https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2016
Upstream changeset:
[2] http://git.clamav.net/gitweb?p=clamav-devel.git;a=commitdiff;h=f0eb394501ec21b9fe67f36cbf5db788711d4236
CVE Request:
[3] http://www.openwall.com/lists/oss-security/2010/05/21/5
Discussion:
This issue affects the current vers
http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=commitdiff%3Bh=f0eb394501ec21b9fe67f36cbf5db788711d4236#patch2http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055771.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055777.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39895http://secunia.com/advisories/43752http://www.mandriva.com/security/advisories?name=MDVSA-2010:110http://www.securityfocus.com/bid/40317http://www.securitytracker.com/id?1024017http://www.vupen.com/english/advisories/2010/1214https://exchange.xforce.ibmcloud.com/vulnerabilities/58824https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2016http://git.clamav.net/gitweb?p=clamav-devel.git%3Ba=commitdiff%3Bh=f0eb394501ec21b9fe67f36cbf5db788711d4236#patch2http://lists.fedoraproject.org/pipermail/package-announce/2011-March/055771.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2011-March/055777.htmlhttp://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://secunia.com/advisories/39895http://secunia.com/advisories/43752http://www.mandriva.com/security/advisories?name=MDVSA-2010:110http://www.securityfocus.com/bid/40317http://www.securitytracker.com/id?1024017http://www.vupen.com/english/advisories/2010/1214https://exchange.xforce.ibmcloud.com/vulnerabilities/58824https://wwws.clamav.net/bugzilla/show_bug.cgi?id=2016
2010-05-26
Published